Example: stock market

ASA FirePOWER (SFR) Module

CHAPTER 26-1 Cisco ASA Series Firewall ASDM Configuration Guide 26 ASA FirePOWER (SFR) ModuleThis chapter describes how to configure the ASA FirePOWER Module that runs on the ASA. The ASA FirePOWER Module , page 26-1 Licensing Requirements for the ASA FirePOWER Module , page 26-5 Guidelines and Limitations, page 26-6 Default Settings, page 26-7 Configuring the ASA FirePOWER Module , page 26-7 Managing the ASA FirePOWER Module , page 26-21 Monitoring the ASA FirePOWER Module , page 26-27 Feature History for the ASA FirePOWER Module , page 26-31 The ASA FirePOWER ModuleThe ASA FirePOWER Module supplies next-generation firewall services , including Next-Generation IPS (NGIPS), Application Visibility and Control (AVC)

The ASA FirePOWER module supplies next-generation firewall services, including Next-Generation IPS (NGIPS), Application Visibility and Control (AVC), URL filtering, and Advanced Malware Protection (AMP).You can use the module in single or multiple context mode, and in routed or transparent mode. The module is also known as ASA SFR.

Tags:

  Services, Module, Firepower, Asa firepower

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of ASA FirePOWER (SFR) Module

1 CHAPTER 26-1 Cisco ASA Series Firewall ASDM Configuration Guide 26 ASA FirePOWER (SFR) ModuleThis chapter describes how to configure the ASA FirePOWER Module that runs on the ASA. The ASA FirePOWER Module , page 26-1 Licensing Requirements for the ASA FirePOWER Module , page 26-5 Guidelines and Limitations, page 26-6 Default Settings, page 26-7 Configuring the ASA FirePOWER Module , page 26-7 Managing the ASA FirePOWER Module , page 26-21 Monitoring the ASA FirePOWER Module , page 26-27 Feature History for the ASA FirePOWER Module , page 26-31 The ASA FirePOWER ModuleThe ASA FirePOWER Module supplies next-generation firewall services , including Next-Generation IPS (NGIPS), Application Visibility and Control (AVC)

2 , URL filtering, and Advanced Malware Protection (AMP).You can use the Module in single or multiple context mode, and in routed or transparent Module is also known as ASA the Module has a basic command line interface (CLI) for initial configuration and troubleshooting, you configure the security policy on the device using a separate application, FireSIGHT Management Center, which can be hosted on a separate FireSIGHT Management Center appliance or as a virtual appliance running on a VMware server. (FireSIGHT Management Center is also known as Defense Center.) How the ASA FirePOWER Module Works with the ASA, page 26-2 ASA FirePOWER Management Access, page 26-4 Compatibility with ASA Features, page 26-5 26-2 Cisco ASA Series Firewall ASDM Configuration Guide Chapter 26 ASA FirePOWER (SFR) Module The ASA FirePOWER ModuleHow the ASA FirePOWER Module Works with the ASAYou can configure your ASA FirePOWER Module using one of the following deployment models: Inline mode In an inline deployment, the actual traffic is sent to the ASA FirePOWER Module , and the Module s policy affects what happens to the traffic.

3 After dropping undesired traffic and taking any other actions applied by policy, the traffic is returned to the ASA for further processing and ultimate transmission. Inline tap monitor-only mode (ASA inline) In an inline tap monitor-only deployment, a copy of the traffic is sent to the ASA FirePOWER Module , but it is not returned to the ASA. Inline tap mode lets you see what the ASA FirePOWER Module would have done to traffic, and lets you evaluate the content of the traffic, without impacting the network. However, in this mode, the ASA does apply its policies to the traffic, so traffic can be dropped due to access rules, TCP normalization, and so forth.

4 Be sure to configure consistent policies on the ASA and the ASA FirePOWER . Both policies should reflect the inline or monitor-only mode of the following sections explain these modes in more FirePOWER Inline ModeIn inline mode, traffic goes through the firewall checks before being forwarded to the ASA FirePOWER Module . When you identify traffic for ASA FirePOWER inspection on the ASA, traffic flows through the ASA and the Module as enters the VPN traffic is policies are is sent to the ASA FirePOWER ASA FirePOWER Module applies its security policy to the traffic, and takes appropriate traffic is sent back to the ASA; the ASA FirePOWER Module might block some traffic according to its security policy, and that traffic is not passed VPN traffic is exits the following figure shows the traffic flow when using the ASA FirePOWER Module in inline mode.

5 In this example, the Module blocks traffic that is not allowed for a certain application. All other traffic is forwarded through the ASA. 26-3 Cisco ASA Series Firewall ASDM Configuration Guide Chapter 26 ASA FirePOWER (SFR) Module The ASA FirePOWER ModuleFigure 26-1 ASA FirePOWER Module Traffic Flow in the ASANoteIf you have a connection between hosts on two ASA interfaces, and the ASA FirePOWER service policy is only configured for one of the interfaces, then all traffic between these hosts is sent to the ASA FirePOWER Module , including traffic originating on the non-ASA FirePOWER interface (because the feature is bidirectional).

6 ASA FirePOWER Inline Tap Monitor-Only ModeThis mode sends a duplicate stream of traffic to the ASA FirePOWER Module for monitoring purposes only. The Module applies the security policy to the traffic and lets you know what it would have done if it were operating in inline mode; for example, traffic might be marked would have dropped in events. You can use this information for traffic analysis and to help you decide if inline mode is desirable. NoteYou cannot configure both inline tap monitor-only mode and normal inline mode at the same time on the ASA. Only one type of security policy is allowed.

7 In multiple context mode, you cannot configure inline tap monitor-only mode for some contexts, and regular inline mode for following figure shows the traffic flow when operating in inline tap mode. ASAMain SystemASA FirePOWERD iverted TrafficASA FirePOWER inspectionVPND ecryptionFirewallPolicyBlockinsideoutsid e371444 26-4 Cisco ASA Series Firewall ASDM Configuration Guide Chapter 26 ASA FirePOWER (SFR) Module The ASA FirePOWER ModuleFigure 26-2 ASA FirePOWER Inline Tap Monitor-Only ModeASA FirePOWER Management AccessThere are two separate layers of access for managing an ASA FirePOWER Module : initial configuration (and subsequent troubleshooting) and policy management.

8 Initial Configuration, page 26-4 Policy Configuration and Management, page 26-5 Initial ConfigurationFor initial configuration, you must use the CLI on the ASA FirePOWER Module . For information on the default management addresses, see Default Settings, page access the CLI, you can use the following methods: ASA 5585-X: ASA FirePOWER console port The console port on the Module is a separate external console port. ASA FirePOWER Management 1/0 interface using SSH You can connect to the default IP address or you can use ASDM to change the management IP address and then connect using SSH.

9 The management interface on the Module is a separate external Gigabit Ethernet cannot access the ASA FirePOWER hardware Module CLI over the ASA backplane using the session command. ASA 5512-X through ASA 5555-X: ASA session over the backplane If you have CLI access to the ASA, then you can session to the Module and access the Module CLI. ASA FirePOWER Management 0/0 interface using SSH You can connect to the default IP address or you can use ASDM to change the management IP address and then connect using SSH. These models run the ASA FirePOWER Module as a software Module . The ASA FirePOWER management interface shares the Management 0/0 interface with the ASA.

10 Separate MAC addresses and IP addresses are supported for the ASA and ASA FirePOWER ASAMain SysteminsideASA FirePOWERASA FirePOWER inspectionoutsideVPND ecryptionFirewallPolicyCopied Traffic371445 26-5 Cisco ASA Series Firewall ASDM Configuration Guide Chapter 26 ASA FirePOWER (SFR) Module Licensing Requirements for the ASA FirePOWER Modulemodule. You must perform configuration of the ASA FirePOWER IP address within the ASA FirePOWER operating system (using the CLI or ASDM). However, physical characteristics (such as enabling the interface) are configured on the ASA. You can remove the ASA interface configuration (specifically the interface name) to dedicate this interface as an ASA FirePOWER -only interface.


Related search queries